First published: Wed Jun 14 2023(Updated: )
An issue was discovered htmlcleaner through version 2.28 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libhtmlcleaner-java | <=2.21-5 | 2.21-5+deb10u1 2.24-1+deb11u1 2.26-1+deb12u1 2.29+dfsg-1 |
ubuntu/libhtmlcleaner-java | <2.21-2ubuntu0.1~ | 2.21-2ubuntu0.1~ |
ubuntu/libhtmlcleaner-java | <2.23-1ubuntu0.1~ | 2.23-1ubuntu0.1~ |
ubuntu/libhtmlcleaner-java | <2.24-1+ | 2.24-1+ |
ubuntu/libhtmlcleaner-java | <2.29 | 2.29 |
maven/net.sourceforge.htmlcleaner:htmlcleaner | <2.29 | 2.29 |
HtmlCleaner | <=2.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34624 has been classified as a denial of service vulnerability.
To fix CVE-2023-34624, upgrade to a version of htmlcleaner later than 2.28.
CVE-2023-34624 affects htmlcleaner versions up to and including 2.28.
CVE-2023-34624 allows attackers to cause a denial of service through crafted objects that use cyclic dependencies.
The vulnerability CVE-2023-34624 is found in the libhtmlcleaner-java package across various distributions.